Re: [Freeipa-users] Limiting Host access by UID/GID

2013-06-06 Thread Jakub Hrozek
On Wed, Jun 05, 2013 at 03:56:25PM -0700, Chandan Kumar wrote: Sorry for late reply. Thanks for helping out. Yes after deleting the sssd cache from /var/lib it does not allow user groups outside min/max_id. Great, I'm glad it works for you now. ___

Re: [Freeipa-users] Limiting Host access by UID/GID

2013-06-05 Thread Chandan Kumar
Sorry for late reply. Thanks for helping out. Yes after deleting the sssd cache from /var/lib it does not allow user groups outside min/max_id. Thanks Chandan On Tuesday, June 4, 2013, Jakub Hrozek wrote: On Fri, May 31, 2013 at 08:50:29AM -0700, Chandan Kumar wrote: As far as my

Re: [Freeipa-users] Limiting Host access by UID/GID

2013-06-04 Thread Jakub Hrozek
On Fri, May 31, 2013 at 08:50:29AM -0700, Chandan Kumar wrote: As far as my understanding goes it does not stop even if I disable cache credentials. I set following parameters in sssd.conf but still UID 2 is able to login. Sorry, there was some terminology confusion. I didn't ask for

Re: [Freeipa-users] Limiting Host access by UID/GID

2013-05-31 Thread Jakub Hrozek
On Thu, May 30, 2013 at 07:23:38PM -0400, Dmitri Pal wrote: On 05/30/2013 06:52 PM, Chandan Kumar wrote: Hello, As part of migration from passwd/shadow to IPA, I want to roll out IPA/SSSD based password first for a small number of users and then for all. (same goes with host. first

[Freeipa-users] Limiting Host access by UID/GID

2013-05-31 Thread Chandan Kumar
As far as my understanding goes it does not stop even if I disable cache credentials. I set following parameters in sssd.conf but still UID 2 is able to login. cache_credentials = False krb5_store_password_if_offline = False min_id=5000 max_id=5010 enumerate = False entry_cache_timeout=3

Re: [Freeipa-users] Limiting Host access by UID/GID

2013-05-30 Thread Dmitri Pal
On 05/30/2013 06:52 PM, Chandan Kumar wrote: Hello, As part of migration from passwd/shadow to IPA, I want to roll out IPA/SSSD based password first for a small number of users and then for all. (same goes with host. first small number of host and then all). I was trying to limit it using